MARSAD
Methodology/ Collaboration workflows

Review, peer-check, sign off, with the working preserved.

Regulators care less about who did the work and more about whether the right people saw it before it stood up. MARSAD's workflow layer is built around that.

What it is

MARSAD's workflow layer is the part of the platform that turns artefacts (findings, attestations, tests, vendor incidents, framework assessments, MVB declarations) into things that move through a defined review-and-sign-off path with an audit trail attached.

It is not a separate tool, and it is not the same shape on every artefact. The shape is matched to what each artefact actually needs.

Why a workflow layer at all

A regulator looking at a sign-off does not just want to see the sign-off, they want to see that the right reviewers saw it at the right time, that there was a peer check, and that the trail is durable. A spreadsheet with three names at the bottom does not produce that confidence.

Internally, the workflow layer is also what stops important work from quietly stalling. An attestation with no owner, a finding past its due date, a framework assessment that nobody has progressed in three months, these surface automatically rather than dying in someone's inbox.

How MARSAD frames it

Each artefact gets a workflow template that fits its risk posture. Some artefacts need a single owner and a peer reviewer. Some need parallel sign-off, chief risk officer and accountable executive on the same declaration, both visible. Some need a lighter touch, an action assigned to an owner with a due date and an automatic chase.

Around the workflow itself, three supports run continuously:

Configurable per framework. Different SAMA frameworks lend themselves to different review patterns. The bank's admin can pick the pattern per framework, so the cyber lens can use four-eyes, the BCM lens can use a single reviewer-plus-sign-off, and the operating team isn't fighting a one-size-fits-all template.

What customers see

Related methodology